DataCarry is a ransomware and data extortion group first observed in May 2025. This group employs a double-extortion model, systematically exfiltrating sensitive data from victim networks before encrypting systems. They then threaten to publish the stolen data on a dedicated Tor-hosted leak site if ransom demands are not met. The group's rapid emergence and international scope across various industries indicate a well-organized operation focused on financial gain through these coercive tactics.
RansomLook pivots
Data, inteligencia y referencias externas para contrastar actividad ransomware del actor.
Construction of BuildingsFood ManufacturingSoftware PublishersReal EstateEnterprises & HoldingAccommodationAir TransportationManufacturingConstructionPublic Administration